Back to Vulnerability Research

CVE-2026-65693

Microweber CMS Server-Side Template Injection via Mail Templates

High · CVSS 4.0 8.6VulnCheckMicroweber CMSCWE-94
Published
July 24, 2026
Affected versions
Through 2.0.20
Researchers
Reju Kole
View on CVE.org

CVE-2026-65693 covers a server-side template injection issue in Microweber CMS mail template rendering.

Authenticated administrators can inject Twig expressions into mail templates that are later rendered in an unsandboxed Twig environment. When application events trigger mail dispatch, those expressions can lead to arbitrary OS command execution on the host.

This is a high-privilege but high-impact pathway: once a malicious template is stored, execution can recur whenever mail events fire. Upgrade to a fixed release where available, restrict admin roles, and validate deployments against the official CVE and advisory references.